home.social

#appsec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #appsec, aggregated by home.social.

  1. Proud to share that @doyensec was trusted by Anthropic as one of the security partners validating #Mythos findings as part of Project #Glasswing!

    Contact us today to see how our research-driven approach shapes the future of #appsec!

    anthropic.com/research/glasswi

    #doyensec #security #ai #claude #claudecode #claudemythos #anthropic

  2. Proud to share that @doyensec was trusted by Anthropic as one of the security partners validating #Mythos findings as part of Project #Glasswing!

    Contact us today to see how our research-driven approach shapes the future of #appsec!

    anthropic.com/research/glasswi

    #doyensec #security #ai #claude #claudecode #claudemythos #anthropic

  3. Proud to share that @doyensec was trusted by Anthropic as one of the security partners validating #Mythos findings as part of Project #Glasswing!

    Contact us today to see how our research-driven approach shapes the future of #appsec!

    anthropic.com/research/glasswi

    #doyensec #security #ai #claude #claudecode #claudemythos #anthropic

  4. Proud to share that @doyensec was trusted by Anthropic as one of the security partners validating #Mythos findings as part of Project #Glasswing!

    Contact us today to see how our research-driven approach shapes the future of #appsec!

    anthropic.com/research/glasswi

    #doyensec #security #ai #claude #claudecode #claudemythos #anthropic

  5. Proud to share that @doyensec was trusted by Anthropic as one of the security partners validating #Mythos findings as part of Project #Glasswing!

    Contact us today to see how our research-driven approach shapes the future of #appsec!

    anthropic.com/research/glasswi

    #doyensec #security #ai #claude #claudecode #claudemythos #anthropic

  6. OWASP Porto had a blast at their latest chapter meeting, celebrating our 25th anniversary in style 🎉 No celebration would be complete without cake! 🎂

    #OWASP #25thanniversary #AppSec #CyberSecurity #OWASPPorto #Community

  7. Больше, чем просто безопасность, или Зачем контролировать зависимости

    Привет, Хабр! Меня зовут Артём Бердашкевич, в Positive Technologies руковожу направления DevSecOps. Сегодня хочу поговорить о теме, которая с годами становится только острее — о контроле зависимостей и о том, почему привычных подходов к нему уже катастрофически не хватает. Современная разработка давно превратилась в сборку из готовых компонентов, где мы почти не пишем код с нуля, а комбинируем фреймворки, библиотеки и модули с открытым исходным кодом. Такой подход радикально ускоряет вывод продуктов на рынок, но за скорость приходится платить прозрачностью. Команда часто не знает точный состав своего приложения до финальной сборки. Почему это стало большой проблемой и что с ней делать — читайте под катом.

    habr.com/ru/companies/pt/artic

    #cybersecurity #devsecops #sca #легаси #зависимости #cve #безопасная_разработка #docker #sandbox #appsec

  8. New #CloudSecTidbits explores how misconfigured AWS ELBs can silently break security boundaries through rule shadowing, CloudFront/WAF bypasses, and alternate routing paths.

    We’re also releasing ELBaph — a new read-only tool to map ELB routing graphs, detect exposed paths, and surface real-world attack chains across ALBs/NLBs.

    blog.doyensec.com/2026/05/25/c

    #AppSec #Doyensec #AWS #CloudSecurity #AppSec #SecurityResearch

  9. New #CloudSecTidbits explores how misconfigured AWS ELBs can silently break security boundaries through rule shadowing, CloudFront/WAF bypasses, and alternate routing paths.

    We’re also releasing ELBaph — a new read-only tool to map ELB routing graphs, detect exposed paths, and surface real-world attack chains across ALBs/NLBs.

    blog.doyensec.com/2026/05/25/c

    #AppSec #Doyensec #AWS #CloudSecurity #AppSec #SecurityResearch

  10. Did you read "No Security Meter for AI" (ref: berryvilleiml.com/docs/no-secu...) If you did, you know that AI should not handle the threat modelling for your software without you double-checking the output. #security #appsec #threatmodeling #ai #machinelearning #ml #games

    berryvilleiml.com/docs/no-secu.....

  11. Did you read "No Security Meter for AI" (ref: berryvilleiml.com/docs/no-secu...) If you did, you know that AI should not handle the threat modelling for your software without you double-checking the output. #security #appsec #threatmodeling #ai #machinelearning #ml

    berryvilleiml.com/docs/no-securi...

  12. Security Tip: Protect your infrastructure by moving away from hardcoded secrets. 🛡️ Storing API keys or database credentials in source code is a recipe for disaster. Instead, use a secrets management tool or environment variables. For maximum security, implement automated rotation to ensure keys expire regularly. This limits the damage if a credential is ever exposed. Stay informed on the latest threats at cvedatabase.com

  13. So I am not allowed to use the word *****, then make sure people have iron balls tied to one of their feet. Unfortunately, it's all too easy to trick an #LLM into doing something it shouldn't do. Which means we really need to think outside the box to #secure them. #appsec #threatmodeling #games

  14. @coreysnipes thank you.

    I have been at this for a while ...both as a security guy who helped get #swsec and #appsec going 28 years ago and as a student of Doug Hofstader's with a Ph.D. in #cogsci. BIML has been spearheading independent #MLsec since 2019.

  15. @coreysnipes thank you.

    I have been at this for a while ...both as a security guy who helped get #swsec and #appsec going 28 years ago and as a student of Doug Hofstader's with a Ph.D. in #cogsci. BIML has been spearheading independent #MLsec since 2019.

  16. @coreysnipes thank you.

    I have been at this for a while ...both as a security guy who helped get #swsec and #appsec going 28 years ago and as a student of Doug Hofstader's with a Ph.D. in #cogsci. BIML has been spearheading independent #MLsec since 2019.

  17. @coreysnipes thank you.

    I have been at this for a while ...both as a security guy who helped get #swsec and #appsec going 28 years ago and as a student of Doug Hofstader's with a Ph.D. in #cogsci. BIML has been spearheading independent #MLsec since 2019.

  18. @coreysnipes thank you.

    I have been at this for a while ...both as a security guy who helped get #swsec and #appsec going 28 years ago and as a student of Doug Hofstader's with a Ph.D. in #cogsci. BIML has been spearheading independent #MLsec since 2019.

  19. #OWASP #Ottawa meetup today

    📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
    📅 Date: May 20, 2026
    ⏰ Time: 6:00 PM EST - Arrival, networking, & pizza! 🍕
    6:30 PM EST - Technical Talks
    #appsec #infosec #cyber

  20. Do you enjoy spending quality time threat modeling? That's fantastic! But, don't forget... "All models are wrong, but some are useful." - George Box Instead, ask yourself, "How often do I do threat modeling with others?" #appsec #owasp #llm #agentic #ai #security #cloud #devops #agile #games

  21. OWASP Cornucopia just released v3.1.0 github.com/OWASP/cornuc... A Special thanks to Prakhar Porwal for implementing the CRE api for the Companion edition (ref: cornucopia.owasp.org/api/docs ). Thank you so much for all your help! #games #cornucopia #owasp #appsec #security #threatmodeling

    Release Release v3.1.0 · OWASP...

  22. More on mythos. #swsec #appsec #MLsec #ML #AI

    "What changed with Mythos Preview is that a model can now take those low-severity bugs (which would traditionally sit invisible in a backlog) and chain them into a single, more severe exploit."

    blog.cloudflare.com/cyber-fron

  23. More on mythos. #swsec #appsec #MLsec #ML #AI

    "What changed with Mythos Preview is that a model can now take those low-severity bugs (which would traditionally sit invisible in a backlog) and chain them into a single, more severe exploit."

    blog.cloudflare.com/cyber-fron

  24. More on mythos. #swsec #appsec #MLsec #ML #AI

    "What changed with Mythos Preview is that a model can now take those low-severity bugs (which would traditionally sit invisible in a backlog) and chain them into a single, more severe exploit."

    blog.cloudflare.com/cyber-fron

  25. More on mythos. #swsec #appsec #MLsec #ML #AI

    "What changed with Mythos Preview is that a model can now take those low-severity bugs (which would traditionally sit invisible in a backlog) and chain them into a single, more severe exploit."

    blog.cloudflare.com/cyber-fron

  26. More on mythos. #swsec #appsec #MLsec #ML #AI

    "What changed with Mythos Preview is that a model can now take those low-severity bugs (which would traditionally sit invisible in a backlog) and chain them into a single, more severe exploit."

    blog.cloudflare.com/cyber-fron

  27. The one good thing about the mythos nonsense is at least broken software is finally being fixed. If that's what it takes, so be it. #swsec #appsec #MLsec

    theguardian.com/technology/202

  28. At AppSec Village, we're proud to have Finite State on board as a Silver Sponsor this year 💀💙

    If connected device security is your world — they're worth knowing!

    ⬇️
    buff.ly/I99VSjM

    #AppSec #IoT #ProductSecurity

  29. Let's talk about security risks from AI, and what to do about them!
    twp.ai/4hr3GS

    Get my free secure coding prompt library here: SecureMyVibe.ca

    #ai #aisecurity #appsec

  30. AI-generated code flagged as a "pain waiting to happen" — and it's a fascinating challenge, not a scandal. When the tool writes the code faster than we can review it, the bottleneck shifts from production to understanding. The real question isn't whether AI can code. It's whether we can keep up with auditing what it builds. 🔍 #infosec #AppSec #AICode
    theregister.com/ai-ml/2026/05/

  31. Registration requirement for access to our new paper "No Security Meter for AI" has been removed due to urgency of content and to promote frictionless distribution

    berryvilleiml.com/results/no-s

    Please consider registering, which enables you to receive email notifications from BIML.

    #MLsec #ML #AI #infosec #swsec #appsec

  32. Registration requirement for access to our new paper "No Security Meter for AI" has been removed due to urgency of content and to promote frictionless distribution

    berryvilleiml.com/results/no-s

    Please consider registering, which enables you to receive email notifications from BIML.

    #MLsec #ML #AI #infosec #swsec #appsec

  33. Registration requirement for access to our new paper "No Security Meter for AI" has been removed due to urgency of content and to promote frictionless distribution

    berryvilleiml.com/results/no-s

    Please consider registering, which enables you to receive email notifications from BIML.

    #MLsec #ML #AI #infosec #swsec #appsec

  34. Registration requirement for access to our new paper "No Security Meter for AI" has been removed due to urgency of content and to promote frictionless distribution

    berryvilleiml.com/results/no-s

    Please consider registering, which enables you to receive email notifications from BIML.

    #MLsec #ML #AI #infosec #swsec #appsec

  35. Registration requirement for access to our new paper "No Security Meter for AI" has been removed due to urgency of content and to promote frictionless distribution

    berryvilleiml.com/results/no-s

    Please consider registering, which enables you to receive email notifications from BIML.

    #MLsec #ML #AI #infosec #swsec #appsec

  36. Have you read BIML's new report No Security Meter for AI?
    #MLsec #ML #AI #swsec #appsec

    berryvilleiml.com/results/no-s

    We removed the reg wall this morning.

  37. Chainguard builds secure-by-default open source — hardened containers, language libraries, and VM images that engineering teams (and their agents) can trust.

    Gold Sponsor at AppSec Village this year — glad to have them in the village.

    images.chainguard.dev/?utm_med

    #AppSecVillage #AppSec #CyberSecurity #SupplyChain #SponsorShoutout

  38. Chainguard builds secure-by-default open source — hardened containers, language libraries, and VM images that engineering teams (and their agents) can trust.

    Gold Sponsor at AppSec Village this year — glad to have them in the village.

    images.chainguard.dev/?utm_med

    #AppSecVillage #AppSec #CyberSecurity #SupplyChain #SponsorShoutout

  39. Chainguard builds secure-by-default open source — hardened containers, language libraries, and VM images that engineering teams (and their agents) can trust.

    Gold Sponsor at AppSec Village this year — glad to have them in the village.

    images.chainguard.dev/?utm_med

    #AppSecVillage #AppSec #CyberSecurity #SupplyChain #SponsorShoutout

  40. Chainguard builds secure-by-default open source — hardened containers, language libraries, and VM images that engineering teams (and their agents) can trust.

    Gold Sponsor at AppSec Village this year — glad to have them in the village.

    images.chainguard.dev/?utm_med

    #AppSecVillage #AppSec #CyberSecurity #SupplyChain #SponsorShoutout

  41. Do you feel like Pablo Escobar waiting for developers to learn threat modeling? The waiting time is over!! #appsec #owasp #llm #agentic #ai #security #cloud #devops #frontend #webdev #threatmodeling #agile #games

  42. Do you feel like Pablo Escobar waiting for developers to learn threat modeling? The waiting time is over!! #appsec #owasp #llm #agentic #ai #security #cloud #devops #frontend #webdev #threatmodeling #agile #games

  43. Do you feel like Pablo Escobar waiting for developers to learn threat modeling? The waiting time is over!! #appsec #owasp #llm #agentic #ai #security #cloud #devops #frontend #webdev #threatmodeling #agile #games

  44. Do you feel like Pablo Escobar waiting for developers to learn threat modeling? The waiting time is over!! #appsec #owasp #llm #agentic #ai #security #cloud #devops #frontend #webdev #threatmodeling #agile #games

  45. Do you feel like Pablo Escobar waiting for developers to learn threat modeling? The waiting time is over!! #appsec #owasp #llm #agentic #ai #security #cloud #devops #frontend #webdev #threatmodeling #agile #games